Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
PaddlePaddle
models
提交
1688818a
M
models
项目概览
PaddlePaddle
/
models
大约 1 年 前同步成功
通知
222
Star
6828
Fork
2962
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
602
列表
看板
标记
里程碑
合并请求
255
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
M
models
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
602
Issue
602
列表
看板
标记
里程碑
合并请求
255
合并请求
255
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
1688818a
编写于
2月 08, 2018
作者:
lyz_sea
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
modify format and test
上级
cfd8a73e
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
45 addition
and
23 deletion
+45
-23
fluid/adversarial/advbox/attacks/saliency.py
fluid/adversarial/advbox/attacks/saliency.py
+33
-5
fluid/adversarial/mnist_tutorial_jsma.py
fluid/adversarial/mnist_tutorial_jsma.py
+12
-18
未找到文件。
fluid/adversarial/advbox/attacks/saliency.py
浏览文件 @
1688818a
...
...
@@ -3,6 +3,8 @@ This module provide the attack method for JSMA's implement.
"""
from
__future__
import
division
import
logging
import
random
import
numpy
as
np
from
.base
import
Attack
...
...
@@ -33,9 +35,13 @@ class SaliencyMapAttack(Attack):
adversary: The Adversary object.
"""
assert
adversary
is
not
None
assert
(
adversary
.
target_label
is
None
)
or
adversary
.
is_targeted_attack
target_labels
=
[
adversary
.
target_label
]
if
not
adversary
.
is_targeted_attack
or
(
adversary
.
target_label
is
None
):
target_labels
=
self
.
_generate_random_target
(
adversary
.
original_label
)
else
:
target_labels
=
[
adversary
.
target_label
]
for
target
in
target_labels
:
original_image
=
adversary
.
original
...
...
@@ -60,6 +66,9 @@ class SaliencyMapAttack(Attack):
if
not
any
(
mask
):
return
adversary
logging
.
info
(
'step = {}, original_label = {}, adv_label={}'
.
format
(
step
,
adversary
.
original_label
,
adv_label
))
# get pixel location with highest influence on class
idx
,
p_sign
=
self
.
_saliency_map
(
adv_img
,
target
,
labels
,
mask
,
fast
=
fast
)
...
...
@@ -80,7 +89,26 @@ class SaliencyMapAttack(Attack):
adv_img
=
np
.
clip
(
adv_img
,
min_
,
max_
)
return
adversary
def
_generate_random_target
(
self
,
original_label
):
"""
Draw random target labels all of which are different and not the original label.
Args:
original_label(int): Original label.
Return:
target_labels(list): random target labels
"""
num_random_target
=
1
num_classes
=
self
.
model
.
num_classes
()
assert
num_random_target
<=
num_classes
-
1
target_labels
=
random
.
sample
(
range
(
num_classes
),
num_random_target
+
1
)
target_labels
=
[
t
for
t
in
target_labels
if
t
!=
original_label
]
target_labels
=
target_labels
[:
num_random_target
]
# str_target_labels = [str(t) for t in target_labels]
# logging.info('Random target labels: {}'.format(', '.join(str_target_labels)))
return
target_labels
def
_saliency_map
(
self
,
image
,
target
,
labels
,
mask
,
fast
=
False
):
"""
...
...
@@ -108,10 +136,10 @@ class SaliencyMapAttack(Attack):
],
0
)
# compute saliency map (take into account both pos. & neg. perturbations)
salmap
=
np
.
abs
(
alphas
)
*
np
.
abs
(
betas
)
*
np
.
sign
(
alphas
*
betas
)
sal
_
map
=
np
.
abs
(
alphas
)
*
np
.
abs
(
betas
)
*
np
.
sign
(
alphas
*
betas
)
# find optimal pixel & direction of perturbation
idx
=
np
.
argmin
(
salmap
)
idx
=
np
.
argmin
(
sal
_
map
)
idx
=
np
.
unravel_index
(
idx
,
mask
.
shape
)
pix_sign
=
np
.
sign
(
alphas
)[
idx
]
...
...
fluid/adversarial/mnist_tutorial_jsma.py
浏览文件 @
1688818a
...
...
@@ -75,28 +75,22 @@ def main():
m
=
PaddleModel
(
fluid
.
default_main_program
(),
IMG_NAME
,
LABEL_NAME
,
logits
.
name
,
avg_cost
.
name
,
(
-
1
,
1
))
attack
=
SaliencyMapAttack
(
m
)
target_label
=
1
print
(
'target_label = %d'
%
target_label
)
total_num
=
0
success_num
=
0
for
data
in
train_reader
():
# JSMA attack
if
target_label
==
data
[
0
][
1
]:
continue
print
(
'original label =%d, target_label = %d'
%
(
data
[
0
][
1
],
target_label
))
adversary
=
Adversary
(
data
[
0
][
0
],
data
[
0
][
1
])
adversary
.
set_target
(
True
,
target_label
=
target_label
)
jsma_attack
=
attack
(
adversary
)
if
jsma_attack
.
is_successful
():
total_num
+=
1
# adversary.set_target(True, target_label=target_label)
jsma_attack
=
attack
(
Adversary
(
data
[
0
][
0
],
data
[
0
][
1
]))
if
jsma_attack
is
not
None
and
jsma_attack
.
is_successful
():
# plt.imshow(jsma_attack.target, cmap='Greys_r')
# plt.show()
print
(
'adversary examples label =%d'
%
jsma_attack
.
adversarial_label
)
np
.
save
(
'adv_img'
,
jsma_attack
.
adversarial_example
)
success_num
+=
1
print
(
'original_label=%d, adversary examples label =%d'
%
(
data
[
0
][
1
],
jsma_attack
.
adversarial_label
))
# np.save('adv_img', jsma_attack.adversarial_example)
print
(
'total num = %d, success num = %d '
%
(
total_num
,
success_num
))
if
total_num
==
100
:
break
break
if
__name__
==
'__main__'
:
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录